Jump to content

Recommended Posts

Posted
I'm trying to get my head around GDPR and what we need to do here in school to be compliant.....Does the server need to be encrypted? It's locked away in my office where pupils, etc. are not allowed. Staff all have encrypted USB sticks already, any laptops that have offline files enabled and that leave school are encrypted with Bitlocker. I take it PC's that would not leave school and don't have offline files enabled would not need to be encrypted? Thanks
Posted
Probably fine unencrypted, likewise PCs. I did in the end encrypt my PC because we were getting a lot of break-ins, but ordinarily non-removable machines in a locked, controlled environment don't need encrypting.
Posted
I'm trying to get my head around GDPR and what we need to do here in school to be compliant.....Does the server need to be encrypted?

 

AFAIK there isn't a "one weird trick to being GDPR compliant, data commissioners hate it when you do this but they can't stop you" answer like "yes it needs to be encrypted" or "no, it doesn't".

 

There needs to be an assessment of what data you have, how its used, what the risks are, etc. and there needs to be a policy that reflects appropriate storage and use of that data that needs to be properly implemented and controlled.

 

You might decide that data needs to be encrypted "at rest" on the server or you might not, this depends on what you think the risks are. For example, do lots of people have admin access to the server? Is sensitive data held on shares or other services that are more open than they need to be, etc.

Posted (edited)
AFAIK there isn't a "one weird trick to being GDPR compliant, data commissioners hate it when you do this but they can't stop you" .

 

I love this comment! :D

 

I always think that if a device has an considerable amount of personal data stored on it, then the default position should be that it is encrypted at rest.

 

If the device was stolen could an attacker get access to any personal data stored on the server? If the answer is yes, then given how easy it is to implement encryption then why wouldn’t you want to protect your data? (That's a rhetorical questions I'm not actually asking it lol)

 

If the server is an admin server, and it contains any data about a person’s ethnicity, religion, wages, disciplinary action, health, disabilities, LAC, CIN etc, then that is an even stronger argument that it should be encrypted.

Edited by rom1984
Posted
I'm trying to get my head around GDPR and what we need to do here in school to be compliant.....Does the server need to be encrypted? It's locked away in my office where pupils, etc. are not allowed. Staff all have encrypted USB sticks already, any laptops that have offline files enabled and that leave school are encrypted with Bitlocker. I take it PC's that would not leave school and don't have offline files enabled would not need to be encrypted? Thanks

What level of physical security controls govern your school premises and your office where the server resides? Like others have said this needs to form part of a risk assessment really, I will not be encrypting servers here due to the physical security controls and measures we have put in place and the fact they reside in a low risk location. Your biggest risk are your USB sticks and laptops leaving the school site with offline sync but it sounds like these are already encrypted :). I would consider your remote access solution, where you store your backups (encrypted or not) and analyse existing password policies to look at potential data issues surrounding these. I recently created a new password policy and used MS fine grained password policies - because one didn't exist and users were able to choose any length password - not good at all.

I'm not sure how much progress you have made in terms of GDPR, but we started by performing a data mapping exercise which enabled us to figure out where data is stored across the network and in paper records in cabinets/cupboard etc. We have a GDPR working party, 6 members - two SLT, one teacher, IT manager, Office Manager and HR manager. We are arranging for a shredding company to come to site in the near future to do a huge 'spring clean' of old paper records, CD's etc.

 

From an IT perspective, ensure appropriate permissions are configured for file access and systems you use. Check through your AD structure and disable accounts that are questionable and may be an easy back door, including admin accounts you may have configured for external vendors/support services. I disable these and enable when I need assistance. On the back of that investigate which cloud services your school uses , question Heads of Departments etc to get a broader sense of what is being used because if your school is anything like ours, I'm sure teacher x y and z took it upon themselves to upload a csv to a cloud site without consulting IT. Once you have a list (it may not be exhaustive) create a data sharing agreement to send to all of your data processor, i'm sure there will be samples on Edugeek that you can use, these act as an agreement between you and company X.

 

We are trying to simplify our data storage practices, given that we suspect an increase in Subject Access Requests, perhaps investigate how you would currently deal with a SAR, should somebody ask for every piece of data you hold on them. Whatever you do now, needs to make responding to SAR's easier moving forward. Data consolidation vs Single point of failure..

In truth, I don't see any school being 100% compliant by 25th May, but if you can prove you are trying your best to work towards compliance and can clearly demonstrate this, the ICO will look favourably on your school should a breach occur.

  • Thanks 1
Posted (edited)

Basically we have two servers....the admin one is in the main school office which is locked at night, cable locked to the wall, alarms set, and not easy access. The other is in my office, cable locked to the wall, doors locked, etc. Our backups are run by Redstor so is secure.

 

I do need to look at the password policy now that you mentioned it as I'm aware some staff have very simple passwords. From the info you mentioned it at least gives me a good start and idea on what to look at.

 

I think the problem here were I work is that we have not had one meeting yet about GDPR. The Head Teacher is looking at it, and mentioned sometime back about we need to have a meeting soon about this, but that has not happened yet. I'm trying to find out at least what I need to do on the IT side to make sure we are as compliant as possible from what I can do on my end. The most I have been asked for is a list of suppliers we use in relation to IT. I just don't want everything to be a last minute rush trying to get compliant or things rushed in place without thought behind it.

Edited by Anothername
Posted

For someone that is new to GDPR these are the four questions that I advise a company to concentrate on. Once these are done you'd be 90% on your way!

 

Do we know what personal data we hold?

 

Do we know where this data is stored?

 

Is it kept securely? (If so, how)

 

Are we transparent with parents/students on what data we have and why we require it?

 

For security it comes down to risks vs what technology is available to mitigate the risk vs the costs to implement it vs what kind of data are you holding. For public sector authorities, especially schools, my general advise is to have a low risk appetite.

 

So if there is an opportunity to put extra security measures in place, and it isn't going to cost the school substantial costs or resources, then my advise would be to do it. The ICO is preparing to put out some detailed guidance on GDPR security soon, once it is out I'l pop on message on this thread to point you to it.

  • Thanks 2
Posted
For GDPR inset day I forced everyone to reset their pw, after setting complexity requirements, so now they're all complex.

 

I predict Finance will be asked to purchase more sticky notes. ;)

  • Thanks 1
Posted
I'm trying to get my head around GDPR and what we need to do here in school to be compliant.....Does the server need to be encrypted? It's locked away in my office where pupils, etc. are not allowed. Staff all have encrypted USB sticks already, any laptops that have offline files enabled and that leave school are encrypted with Bitlocker. I take it PC's that would not leave school and don't have offline files enabled would not need to be encrypted? Thanks

 

Nope.

 

It sounds like you are perfectly okay in regards to security and encrypted portable devices.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...